Categories: Ad Guardian PlusNews

Malware hits Euro Cup and Olympics Ticket Reseller

 JavaScript that steals payment card data hit a re-seller of tickets for Euro Cup and Olympics. The code survived for at least 50 days on one of the websites. On the other one, it lasted for two weeks. This ended due to the intervention of two security specialists.

The code which steals card credentials from online stores at checkout is MageCart. The name comes from the fact it initially targeted sites running Magento e-commerce platform.

Jacob Pimental discovered the skimmer on the secondary ticket market OlympicTickets2020.com. The skimmer was hiding in a legitimate library – Slippry. It went active when the slider loaded. The malicious code was planted in the library in an obscure form.

After he had met the loader code responsible for launching the skimmer in March 2019, Max Kersten, a security researcher, helped Pimental. “The structure of the loader is, aside from the random variable names and script content, exactly the same,” Kersten wrote in a post.

Pimental discovered that specific keywords triggered the script. Thus, these were usually associated with a payment page: onepage, checkout, store, cart, pay, order, basket, billing, order. “If it finds any of those keywords in the website, it will send the information in the credit card form to opendoorcdn[.]com,” he wrote in a post.

The altered Slippry did not load from a third-party location that could have been compromised. So, Pimental searched for the hash of the library on UrlScan. Thus, he found that it was present on another site, EuroTickets2020.com, also in the ticket reselling business.

He discovered that the same party operated both EuroTickets2020 and OlympicTickets2020. Afterwards, he revealed that MageCart was present on the OlympicTickets site since at least December 3, 2019. On EuroTickets it was active since at least January 7, 2020.

A problem hard to solve

Although the two researchers tried to contact the owner of the websites, they received no answer. After their second contact, the security team decided to close the case. 

Still, they  insisted on the issue and provided clear instructions. But the two websites continued to host the malicious script. However, they removed MageCart, eventually.

They both warn that shopping at Euro Cup and Olympics Ticket re-seller  between December 3, 2019, and January 21, 2020, likely resulted in compromising card data. So, the best thing to do is contacting the issuing bank and requesting a card replacement.

Million Insights warned at the end of the last year about the phishing an malware threats until 2025.

Laurentiu Titei

Recent Posts

Computer Runs Slowly? Here Are the Tips to Speed Up Windows PC

Have you noticed that your computer runs slowly? Are you frustrated by frequent system freezes,…

12 hours ago

How to Fix Wifi Network Not Showing Up on Windows PC

If you're encountering the Wifi network not showing up on laptop error on your Windows…

3 days ago

Guide on How to Fix Fatal System Error in Windows 10

Are you encountering a Fatal System error in Windows 10? Don’t worry, try these simple…

5 days ago

Update Graphics Drivers in Windows 11,10, 8 & 7 (Manually & Automatic)

Refer to our guide to learn manual and automatic ways to download, install, and update…

1 week ago

Epson Printer Driver Download and Update for Windows 10, 11

A correct Epson printer driver facilitates smooth printing performance. Hence, you can continue reading this…

1 week ago

Halo Infinite Keeps Crashing on Windows PC: Fixed

If you are also facing the Halo Infinite crashing error on your Windows PC, then…

1 week ago